63 Total
12 High severity
36 Medium severity
15 Low severity
Summary

This is Stripe's public disclosure list of the third-party companies and internal affiliates that process personal data on behalf of Stripe's business customers, updated December 20, 2025. The document states that Business Users operating under Stripe's Data Processing Agreement have 30 days from any page update to object in writing to a new sub-processor, and that silence within that window is treated as acceptance. The update adds several new entities including sub-processors for Japan payment integration (NETSTARS Co., Ltd.), check scanning (Jack Henry & Associates, Inc. and Mitek Systems, Inc.), stablecoin and crypto services (Horkos, Inc., Bridge Ventures, LLC, and related Bridge entities), and a new EMEA and APAC data controller (Stripe Technology Company Limited).

Technical / Legal Breakdown

This document is Stripe's Sub-processor and Affiliate Disclosure List, last updated December 20, 2025, published pursuant to GDPR and other global privacy frameworks that require data processors to maintain and disclose sub-processor arrangements when processing personal data on behalf of business customers. The document states that Business Users may object in writing to the appointment of a new sub-processor within 30 days of a page update, and that failure to object within this window is deemed acceptance under the terms of Stripe's Data Processing Agreement. The document discloses a materially expanded affiliate network including newly added entities in the stablecoin and crypto space (Horkos, Inc., Bridge Ventures, LLC, Bridge Building Sp. Z.o.o., Bridge Building S.A., and Stripe Global Technology, LLC), a newly designated EMEA and APAC data controller (Stripe Technology Company Limited), and the conversion of Stripe, Inc. to Stripe, LLC effective January 3, 2026, each of which may trigger data mapping, DPA review, and regulatory notification obligations for affected Business Users. The document engages GDPR sub-processor notification requirements, India's data localization regulations (referenced for Stripe India Private Limited), and financial services regulatory frameworks in Ireland (Central Bank of Ireland), the UK (FCA), and multiple APAC and LATAM jurisdictions. Compliance teams in the EU, UK, and other jurisdictions with formal DPA structures should evaluate whether the newly listed entities, particularly those handling stablecoin and crypto-related personal data, fall within the scope of existing contractual sub-processor consent mechanisms and require updated data transfer impact assessments.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Get Compliance
Featured — High severity
Featured — Medium severity

Complete Provision Index

Every distinct legal provision identified in this document. Featured provisions appear above with analysis.

63 provisions
12 featured
11 clause types
12 high severity
data_sharing 39
other 14
data_retention 2
ai_automated 1
contract_terms 1
data_collection 1
data_usage 1
disclosure_requirements 1
platform_discretion 1
policy_changes 1
privacy_rights 1

Monitoring

Stripe has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Get Compliance

Cross-platform context

See how other platforms handle 30-Day Written Objection Right For New Sub-Processor and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
ePrivacy Directive
European Union
View official text ↗
FCRA
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
GLBA
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗

Related Analysis

Consumer Rights · April 21, 2026
Stripe's Reserve and Hold Authority: What the Terms Authorize

Stripe's terms authorize fund reserves, payout withholding, and account termination. Here is what the agreement states and what business ow…

Dependency Governance · May 27, 2026
When Infrastructure Providers Govern Platforms

The Kickstarter-Stripe controversy reveals how payment processors, cloud providers, and AI platforms quietly shape downstream policy decisi…

Dependency Governance · June 11, 2026
When AI Agents Start Paying for Things: Who Governs Machine-to-Machine Commerce?

Mastercard, Stripe, and Cloudflare are building payment infrastructure for autonomous AI agents. The governance layer is not keeping pace.

Archival ProvenanceSource & Archival Record
Last Captured July 6, 2026 22:43 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000929
Version ID CA-V-004527
SHA-256 d3bbbafbfb8cc4491fca587f4ef263fec6efb936c8a1da023ea29df350bec630
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans